Impact Advisors
Building a Third-Party Risk Management Program for Healthcare
Pages
2
Time to read
3 mins
Publication
Language
English
Pages
2
Time to read
3 mins
Publication
Language
English
This case study outlines the development of a Third-Party Risk Management (TPRM) program for a regional health system in response to increased scrutiny following significant security breaches. The organization recognized the limitations of relying solely on vendor questionnaires for assessing risk and sought to establish a comprehensive program to monitor and manage vendor risk effectively. The engagement with Impact Advisors involved creating a structured approach that included developing a complete inventory of vendors, categorizing them by risk tier, and implementing a risk-based assessment framework. Key enhancements were made to procurement processes and vendor contracts to ensure accountability and compliance. Continuous monitoring was integrated into Security Operations Center workflows to provide real-time visibility into vendor risks. The program's success was attributed to factors such as visibility before assessment, risk-based prioritization, enforceable contracts, and operational integration. This initiative aimed to reduce the likelihood and impact of third-party-driven incidents within the healthcare ecosystem.